CVE-2025-8708

MEDIUM

Antabot White-jotter - Insecure Deserialization

Title source: rule

Description

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input EVANNIGHTLY_WAOU leads to deserialization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 5.0
EPSS 0.0006
EPSS Percentile 18.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-502 CWE-20
Status published

Affected Products (1)

antabot/white-jotter

Timeline

Published Aug 08, 2025
Tracked Since Feb 18, 2026